How fast could your business respond to a cyber attack? Free 10-question assessment measures your incident response readiness with actionable recommendations.
When a cyber attack hits, the first 60 minutes determine the outcome. Businesses that respond quickly contain the damage. Businesses that don't have a plan lose days — sometimes weeks — to confusion, finger-pointing, and avoidable mistakes.
This free assessment measures how quickly and effectively your business could respond to a real cyber incident. It covers documentation, testing, communication, technical capability, and regulatory compliance. Takes less than 5 minutes.
What You Will Learn
- Your estimated response time (under 1 hour to 24+ hours)
- Which areas of your IR capability need immediate attention
- Specific steps to improve your readiness this week
What the Assessment Covers
The 10 questions span seven areas of incident response capability: documentation, testing, communication, recovery, regulatory obligations, technical capability, and continuous improvement.
- A written incident response plan, approved by management and accessible to the team — without a plan, the first hour of an incident is wasted on deciding what to do.
- Testing within the last 12 months (tabletop exercise or simulation) — an untested plan is a guess; plans go stale as staff, systems, and threats change.
- An up-to-date emergency contact list including IT, legal, insurance broker, DPC, NCSC, and Gardaí — accessible offline in case your systems are down.
- Clearly assigned incident response roles: who leads, who communicates, who handles technical response — without clear roles, everyone waits for someone else to act.
- Tested backup restores in the last 6 months and a known full restore time — untested backups are assumptions, not guarantees.
- Knowledge of GDPR 72-hour breach notification obligations and a named person responsible for notifying the DPC — the clock starts when you become aware.
- Pre-drafted communication templates for customers, staff, and media — writing communications during a crisis leads to mistakes and inconsistencies.
- Cyber insurance policy details, broker's emergency line, and coverage knowledge — you need to know what's covered before the incident, not during.
- The ability to isolate an infected device or network segment within 30 minutes — the difference between one infected device and a full network compromise.
- Formal lessons-learned reviews after incidents or near-misses — without them, the same mistakes happen again.
How Scoring Works
Each question scores 0 to 3 points, giving a maximum of 30. Your percentage maps to a readiness level with an estimated effective response time: 80% or above is Incident Ready (estimated effective response under 1 hour), 60-79% is Partially Ready (2-6 hours), 40-59% is Significant Gaps (6-24 hours), and below 40% is Not Ready (24+ hours, with critical delays likely). Results also break your score down by category, rating each as Strong, Needs Improvement, or Critical Gap.
Why Response Time Matters
| Response time | Likely outcome |
|---|---|
| Under 1 hour | Contain the breach, preserve evidence, minimise data loss. Best chance of recovery. |
| 1-6 hours | Attacker may have moved laterally. Containment is harder. Some data may be exfiltrated. |
| 6-24 hours | Full network compromise likely. Ransomware deployed. Recovery takes weeks, not days. |
| 24+ hours | Maximum damage. Extended downtime. Regulatory exposure. Reputational harm. |
Who It Is For
The assessment is designed for Irish SMEs that want to know how ready they are before an incident happens. Depending on your result, recommended next steps range from annual tabletop exercises and quarterly plan reviews through to building the basics — a written plan, assigned roles, and an emergency contact list, which can be done in a week. We help Irish SMEs build practical, tested incident response plans — not 50-page documents that nobody reads. Results include a downloadable PDF report.